CVE-2026-65660

sharepoint_server: Improper Control of Generation of Code ('Code Injection') (CVE-2026-65660)

Affected

  • microsoft/sharepoint_server lt *..16.0.19725.20522

Response & Mitigation

Why act now?

Prioritisation rationale

CVE-2026-65660 carries a CVSS score of 8.8 with the vector AV:N/AC:L/PR:L/UI:N, meaning it is exploitable over the network with low complexity and requires only a standard authenticated user — no administrator account needed. In organisations where SharePoint is broadly deployed as an intranet or collaboration platform with many users holding Contribute rights, the effective attack surface is very large. The EPSS score of 1.19 % (66th percentile) reflects elevated but not yet mass-exploitation risk; however, CISA KEV inclusion confirms active exploitation in the wild, which elevates patch priority to critical regardless of EPSS. NIS2-scoped KRITIS organisations should treat this as a high-severity finding: SharePoint commonly holds sensitive documents and business-process data, and successful exploitation yields full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) on the affected host, with realistic paths to broader domain compromise via the service account context.

Runbook · Step 1

Immediate response (0-24 h)

  • Apply the vendor patch immediately: the affected baseline version is SharePoint Server 16.0.19725.20522. Retrieve the exact patch ID and download link from the current Microsoft Security Response Center (MSRC) advisory and deploy it across all SharePoint farms without delay.
  • Isolate any internet-facing or reverse-proxy-exposed SharePoint farms, or enforce an additional authentication layer (e.g. Azure AD Application Proxy with MFA) in front of them until the patch is confirmed deployed.
  • Treat all SharePoint service accounts (Farm Account, App Pool identities, Search Service Account) as potentially compromised: rotate passwords immediately, purge Kerberos tickets (klist purge on affected servers), and evaluate whether a krbtgt reset is warranted.
  • Restrict inbound HTTP/HTTPS traffic (port 443, optionally 80) to SharePoint servers at the WAF or reverse proxy layer — temporarily allowlist only known source ranges and alert on POST requests to /_layouts/, /_api/, and /_vti_bin/ endpoints.
  • Audit local administrator memberships on all SharePoint servers: only Farm Administrator accounts should hold local admin rights; remove all others immediately.

Runbook · Step 2

Mitigation layers

  • Network segmentation: Place SharePoint servers in a dedicated VLAN and block outbound connections from those servers to the internet and to Tier-0 assets (Domain Controllers, PKI) — this limits lateral movement if code injection succeeds.
  • WAF/IPS rule: Deploy a Snort/Suricata signature targeting suspicious POST payloads on SharePoint endpoints: alert http any any -> $SHAREPOINT_SERVERS 443 (msg:"CVE-2026-65660 SharePoint Code Injection attempt"; content:"POST"; http_method; content:"/_layouts/"; http_uri; pcre:"/(<script|eval\(|System\.Reflection|Assembly\.Load)/i"; sid:9266560; rev:1;).
  • Least privilege / IAM: Audit SharePoint user permissions and remove unnecessary Contribute and Design rights — because the vulnerability requires only a low-privileged authenticated user (PR:L), reducing the population of users with write access directly shrinks the attack surface.
  • Endpoint hardening: Enable AppLocker or Windows Defender Application Control (WDAC) on SharePoint servers to prevent the IIS worker process (w3wp.exe) from spawning unsigned binaries or executing arbitrary PowerShell.
  • Configuration change: Disable SharePoint Solution Deployment and Farm Feature Activation on production systems unless operationally required — these are common code-injection vectors that should not be available in a hardened production farm.

Runbook · Step 3

Detection rules

  • Windows Security Event ID 4688: Monitor for process creation on SharePoint servers where the parent process is w3wp.exe and the child is cmd.exe, powershell.exe, csc.exe, or msbuild.exe — a strong indicator of successful code injection. KQL: SecurityEvent | where EventID == 4688 and ParentProcessName has "w3wp.exe" and NewProcessName has_any ("cmd.exe","powershell.exe","csc.exe","msbuild.exe").
  • Sysmon EID 1 / EID 3: Alert on process creation by w3wp.exe with unusual command-line arguments, and on outbound network connections from w3wp.exe to external IPs (Sysmon EID 3) — neither should occur in normal SharePoint operation.
  • IIS access logs / web telemetry: Flag HTTP POST requests returning status 200 to /_layouts/15/, /_api/web/, or /_vti_bin/ with unusually large request bodies (> 50 KB) or Base64-encoded content in the body. SPL: index=iis cs_method=POST cs_uri_stem="*/_layouts/*" sc_status=200 cs_bytes>51200.
  • Sigma rule (shape): title: SharePoint w3wp Child Process / logsource: category: process_creation, product: windows / detection: selection: ParentImage|endswith: '\w3wp.exe', Image|endswith: ['\cmd.exe','\powershell.exe','\csc.exe'] / condition: selection.
  • EDR telemetry: File-write events by w3wp.exe outside the SharePoint hive (C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\) — writes to %TEMP%, %APPDATA%, or C:\Windows\Temp are strong indicators of dropper activity following successful exploitation.

Description

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

microsoftsharepoint_server
16.0.19725.20522fixed from 16.0.19725.20522

Metrics

8.8
Source: nvd-v3
81.2 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Actively exploited
Show all metrics
Severity
critical
actively exploited (KEV)
2.1 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-08-11 17:18 UTC
CWE-94

Weakness classes (CWE)

  • CWE-94Base

    Improper Control of Generation of Code ('Code Injection')

    The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

    cwe.mitre.org →

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-26 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-65660","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
    • SSVC: {"id":"CVE-2026-65660","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
  2. Modified Analysis2026-09-25 17:00 UTC· nvd@nist.gov
    • Reference Type: CISA-ADP: https://blog.previdian.com/cve-2026-65660-previdian-observes-two-stage-sharepoint-exploitation-attempts/ Types: Third Party Advisory
    • Reference Type: CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65660 Types: US Government Resource
  3. CVE Modified2026-09-25 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://blog.previdian.com/cve-2026-65660-previdian-observes-two-stage-sharepoint-exploitation-attempts/
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65660
    • SSVC: {"id":"CVE-2026-65660","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
    • SSVC: {"id":"CVE-2026-65660","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
  4. CVE CISA KEV Update2026-09-25 16:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
    • Date Added: 2026-09-25
    • Due Date: 2026-09-25
    • Required Action: 2026-09-25
    • Vulnerability Name: 2026-09-25
  5. CVE Modified2026-09-25 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-65660","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
    • SSVC: {"id":"CVE-2026-65660","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…

Linked advisories